Back

HIGH

Unrestricted Upload of Files in edu-sharing

Published Jun 20, 2024

Description

An authenticated user can upload arbitrary files in the upload function for collection preview images. An attacker may upload an HTML file that includes malicious JavaScript code which will be executed if a user visits the direct URL of the collection preview image (Stored Cross Site Scripting). It is also possible to upload SVG files that include nested XML entities. Those are parsed when a user visits the direct URL of the collection preview image, which may be utilized for a Denial of Service attack.

This issue affects edu-sharing: <8.0.8-RC2, <8.1.4-RC0, <9.0.0-RC19.

Affected products

Remediation

Vendor solution

The repository base version in use can be identified in the Admin-Tools. The vendor provides a patch for the affected versions:

* Version 8.0: Update repository version to "8.0.8-RC2" or later * Version 8.1: Update repository version to "8.1.4-RC0" or later * Version 9.0: Update repository version to "9.0.0-RC19" or later

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner SEC-VLab
Published Jun 20, 2024
Updated Feb 13, 2025
Reserved Mar 5, 2024
CISA Vulnrichment
Updated Jul 31, 2024
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner SEC-VLab
Published Jun 20, 2024
Updated Feb 13, 2025
Exploited since n/a
EUVD-2024-25294